Back to skill

Security audit

Workflow Dlc Agent Learning

Security checks for vulnerabilities and agentic risk

Overview

The skill is not executable malware, but it tells agents to build broad always-on logging, reporting, and long-term reuse of interaction data without enough privacy controls.

Review this skill before installing in any environment that may process personal data, credentials, customer data, confidential business configuration, or regulated compliance information. It should only be used with explicit privacy requirements: redact secrets and personal data before storage, aggregate or anonymize reports, restrict Feishu/report recipients, define role-based access, set retention and deletion rules, and require human approval before any learned rule changes agent behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:34
Finding

Excessive Interaction Telemetry Without Defined Privacy or Security Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 34–41
Vulnerability Type: Privacy-invasive telemetry and insecure sensitive-data logging
Risk Level: Medium

Vulnerable Snippet

text
├── meta:operation_id / timestamp / operator / page_context / config_type
├── geo:region / country / city / timezone / locale / currency
├── interaction:user_input / input_type(natural_language|quick_action|template) /
│               agent_parse / agent_questions / form_filled / user_modified /
│               final_submitted
├── execution:api_calls / cross_system / validation_results / submit_status
├── compliance:rules_checked[] / rules_passed[] / rules_blocked[] / override_reason
├── localization:languages[] / currency / tax_rules_applied
├── calendar:nearby_events[] / cultural_flags[]

Technical Analysis

The Skill requires every interaction to be logged and defines a broad telemetry schema containing operator identity, raw user input, Agent-generated content, form values, final submissions, precise geographic context, API activity, cross-system activity, compliance decisions, and calendar-related information.

The surrounding workflow also requires periodic analysis, delivery of reports to Feishu, and eventual movement of older raw records into cold storage. However, it does not define:

  • Redaction of credentials, authentication tokens, personal data, or confidential business information.
  • Purpose-based field minimization or restrictions on recording raw prompts and API payloads.
  • User notice or consent requirements.
  • Encryption in transit or at rest.
  • Role-based access controls or tenant isolation.
  • Sanitization before reports are delivered to an external collaboration platform.
  • A verified deletion process or user-controlled retention policy.
  • Restrictions against using sensitive raw records for AI analysis.

Consequently, an implementation that follows these instructions litera ...[truncated 1915 chars]

Remediation
View remediation

Remediation Suggestions

  1. Apply data minimization

    • Do not record raw prompts, complete API payloads, credentials, tokens, or final submissions by default.
    • Replace operator identities with scoped pseudonymous identifiers where attribution is not essential.
    • Reduce precise city-level location to the minimum geographic granularity required.
  2. Add mandatory secret and personal-data filtering

    • Detect and redact passwords, access tokens, API keys, session cookies, payment data, and regulated personal information before persistence.
    • Perform filtering before data is sent to AI analysis or external reporting systems.
    • Reject or quarantine records when safe redaction cannot be guaranteed.
  3. Define access controls

    • Enforce least-privilege, role-based access for logs, reports, and cold storage.
    • Isolate records by tenant, region, and environment.
    • Record and monitor every read, export, modification, and deletion operation.
  4. Protect stored and transmitted data

    • Require authenticated encryption at rest and TLS for all data transfers.
    • Store encryption keys in a managed key service with rotation and separation of duties.
    • Prohibit plaintext exports and unrestricted report links.
  5. Secure external reporting

    • Send only aggregated and anonymized statistics to Feishu.
    • Exclude raw prompts, operator identities, precise locations, API details, and low-volume categories that could permit re-identification.
    • Require an approved destination, restricted membership, expiration controls, and data-loss-prevention scanning.
  6. Implement retention and deletion controls

    • Establish field-specific retention periods based on necessity rather than moving all records to indefinite cold storage.
    • Support verified deletion from active storage, backups, reports, indexes, and AI-processing datasets.
    • Require explicit approval before extending rete ...[truncated 322 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill mandates automatic logging of every interaction, including user input and user modifications, but does not require notice, consent, minimization, or redaction. This creates a real privacy and compliance risk because free-form inputs can contain personal, sensitive, or confidential business data that is then persistently stored and made available for later analysis.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The logging design captures comprehensive interaction data, including raw user inputs, parsed content, edits, compliance data, geo fields, and quality tags, then retains them for later processing. In context, this broad data collection materially increases privacy, insider access, and secondary-use risks because the system is explicitly designed to centralize and analyze potentially sensitive operational and user-provided content.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The bi-weekly AI reporting workflow instructs the system to aggregate logged interaction data into regional summaries, modification patterns, and candidate rules. Even without obvious malicious intent, this can expose sensitive trends, enable profiling by geography, and propagate confidential user/business data into reports shared with broader teams, increasing the blast radius of any overcollection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill description and operating instructions are presented entirely in Chinese and frame the skill's behavior in that language, with no indication that users may choose another language. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale restriction is justified and documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.